CVE-2020-3530

Description

A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local attacker to execute that command, even though administrative privileges should be required. The attacker must have valid credentials on the affected device. The vulnerability is due to incorrect mapping in the source code of task group assignments for a specific command. An attacker could exploit this vulnerability by issuing the command, which they should not be authorized to issue, on an affected device. A successful exploit could allow the attacker to invalidate the integrity of the disk and cause the device to restart. This vulnerability could allow a user with read permissions to issue a specific command that should require Administrator privileges.

Risk Information

Base Score
8.4
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
EPSS Score
Exploitation Probability
0.03

Associated Vulnerability

VulnerabilityOS Platform
Cisco IOS XR Authenticated User Privilege Escalation Vulnerability For Cisco ASR 9000 Series Aggregation Services RoutersNCM
Cisco IOS XR Authenticated User Privilege Escalation Vulnerability For Cisco Network Convergence System 5500 SeriesNCM
Incorrect Authorization Vulnerability (CVE-2020-3530)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1705564Security Update for Cisco ASR 9000 Series Aggregation Services Routers 5.3.0.1i.BASE
PATCH-1705220Security Update for Cisco Network Convergence System 5500 Series 7.1.2.1i.BASE

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234